CVE-2026-81523 LOW

CVE-2026-81523: Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocrypt

Vendor Mongodb
Product libmongocrypt
Weakness CWE-74
Published August 27, 2026
Last update August 28, 2026

CVSS base score

2.0/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated

Related vulnerabilities

04Related CVE